Britain has weakened proposed cybersecurity protections for its telecoms networks that were developed in response to the Salt Typhoon espionage campaign, after the companies responsible for implementing the measures lobbied against them.
Microsoft Patch Tuesday security updates for June 2026 fix a record 208 CVEs, including one actively exploited zero-day and multiple critical RCE flaws. Microsoft Patch Tuesday security updates for June 2026 mark a record. Microsoft shipped fixes for 208 CVEs across Windows, Office, Azure, Exchange,...
Unless you're an admin or vulnerability manager – then you're totally screwed
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploi...
Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion.
The post Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility appeared first on Unit 42.
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit, which may result in denial of service, information leaks, or potentially remote code execution. Additional details can be found in the upstream advisory: https://openssl-library.org/news/secadv/20260609.txt
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances. [...]
Microsoft Patch Tuesday details for June 2026.
Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users. [...]
Several vulnerabilities were discovered in poppler, a PDF rendering library, which could result in denial of service, information disclosure, or potentially the execution of arbitrary code if a specially crafted file is processed. For the oldstable distribution (bookworm), these problems have been f...
The Senate Judiciary Committee is set to consider and vote on the Nurture Originals, Foster Art, and Keep Entertainment Safe Act (NO FAKES). Instead of targeting the real privacy harms posed by AI-generated replicas, this law would create another layer of internet censorship on top of the already ex...
George Karagiannidis discovered multiple security vulnerabilities in the fax backend of the Okular document viewer, which could potentially result in the execution of arbitrary code if a malformed G3/G4 Fax file is opened. For the oldstable distribution (bookworm), this problem has been fixed
Eduardo Gonzalez Gutierrez and Arnaud Morin discovered that multiple API endpoints of Mistral, the OpenStack Workflow, improperly enforced access policies, which could result in information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 15.0.0-1+deb12u1...
Several security issues were fixed in Vim.
Several security issues were fixed in OpenSSL.
Fears and warnings about a roaring flood of error-riddled software have materialized. And the disease is spreading.
The post Microsoft breaks Patch Tuesday record with 206 vulnerabilities appeared first on CyberScoop.
Anthropic unveiled two new powerful AI models built on its previously restricted Mythos architecture: Claude Fable 5, which is being made broadly available, and Claude Mythos 5, which remains limited to a small group of cybersecurity and infrastructure partners.
Anthropic d...
SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. [...]
USN-8414-1 fixed several vulnerabilities in OpenSSL.